beautypg.com

HP Identity Driven Manager Software Series User Manual

Page 10

background image

1-4

Welcome to Identity Driven Manager
Introduction

Figure 1-1. IDM Architecture

IDM consists of an IDM Agent that is co-resident on the RADIUS server, and an
IDM Server and SNAC server that are co-resident with PCM+. Configuration and
access management tasks are handled via the IDM GUI on the PCM+ management
workstation.

The IDM agent includes:

A RADIUS interface that captures user authentication information from the
RADIUS server and passes the applicable user data (username, location,
time of request) to the IDM Decision Manager. The interface also passes
user access parameters from IDM to the RADIUS server.

A Decision Manager that receives the user data and checks it against user
data in the local IDM data store. Based on the parameters defined in the data
store for the user data received, the Decision Manager outputs access
parameters for VLAN, QoS, bandwidth, and network resource access to the
RADIUS interface component.

A Local Data Store that contains information on Users and the Access Policy
Groups to which the user belongs. The Access Policy Group defines the
rules that determine the user’s access rights.